
The compliance gap most organizations do not see
At its operational core is a compliance risk assessment process that requires organizations to systematically identify their compliance obligations, assess the risks of non-compliance and implement controls proportionate to those risks. Most organizations that believe they are compliant have never conducted this assessment rigorously.
The compliance landscape of 2026 is the most demanding in a generation. Anti-bribery legislation, data protection law, environmental regulation, financial crime controls, trade sanctions, competition law, health and safety obligations and sector-specific regulatory requirements are simultaneously increasing in scope and in enforcement intensity across every major jurisdiction.
Organizations that manage compliance through a legal team tracking known legislation, a code of conduct and an annual training program are operating a compliance awareness program, not a Compliance Management System.
Takeaway: Ask your compliance team to create a current inventory of all applicable obligations; delays beyond one week may indicate gaps.
What ISO 37301 actually requires?
Organizations can now achieve accredited third-party certification against ISO 37301, providing independently audited evidence of CMS design and operational effectiveness.
The standard follows the Annex SL High Level Structure shared by ISO 9001, ISO 27001 and ISO 14001, making it structurally compatible with existing management systems. Its requirements cover:
Identifying compliance obligations: The foundation of everything
The most common and most consequential failure in compliance management is incomplete obligation identification. Organizations that conduct compliance risk assessments without first building a comprehensive, current and structured compliance obligation register are assessing a subset of their actual compliance exposure.
Legal obligations: Applicable legislation across all jurisdictions where the organization operates, sells, employs, sources or processes data
Regulatory obligations: Requirements imposed by sector-specific regulators including financial regulators, environmental agencies, health and safety authorities and data protection supervisory authorities
Judicial and administrative obligations: Court orders, consent decrees, regulatory settlements and administrative decisions binding on the organization
Contractual obligations: Compliance requirements embedded in customer contracts, supplier agreements, partnership arrangements and financing agreements
Voluntary commitments: Industry codes, trade association standards, ESG frameworks and sustainability commitments the organization has publicly adopted
Tip: Structure compliance obligations across all six categories and jurisdictions, reviewing quarterly and updating within 30 days of relevant changes.
Compliance risk assessment: What ISO 37301 clause 6.1.2 requires?
The outputs of the compliance risk assessment must guide the development of controls, monitoring mechanisms and improvement priorities. The compliance risk assessment process requires five structured steps:
Step 1: Obligation mapping
Map each identified compliance obligation to the specific organizational processes, functions, locations and activities to which it applies. Obligations that cannot be mapped to specific operational processes are not manageable and will not be effectively controlled.
Step 2: Inherent risk assessment
For each obligation, assess the inherent likelihood of non-compliance without considering existing controls, and the inherent impact of non-compliance on both the organization and affected parties. Inherent risk assessment produces the raw risk profile before controls are applied.
Step 3: Control effectiveness assessment
Evaluate the effectiveness of existing controls addressing each identified compliance risk. Controls that exist in documented form but are not consistently applied in practice provide less risk reduction than their existence implies. Control effectiveness assessment must be evidence-based, not assumption-based.
Step 4: Residual risk determination
Determine the residual compliance risk after accounting for existing control effectiveness. Residual risks that exceed the organization's defined compliance risk appetite require additional controls or escalation to the governing body for informed risk acceptance decisions.
Step 5: Prioritization and treatment
Prioritize residual compliance risks by severity and develop proportionate treatment plans covering additional controls, process changes, training requirements and monitoring mechanisms.
Writer's view: Assess compliance risks at the obligation level to identify specific regulatory exposures, affected processes and controls rather than aggregated risks.
Where compliance risk assessments most commonly fail?
Organizations that conduct technically sound risk assessments on an incomplete obligation register, organizations that assess inherent risk without evaluating actual control effectiveness, and organizations that produce comprehensive risk assessment outputs that are never reviewed by the governing body are not managing compliance risk, they are documenting it. Common compliance risk assessment failures that ISO 37301 auditors consistently identify:
Incomplete obligation registers: Obligations in non-primary jurisdictions, contractual compliance requirements and voluntarily adopted industry codes are the most frequently omitted categories
Aggregated risk entries: Domain-level risk entries such as "financial crime risk" or "environmental compliance risk" without obligation-level decomposition prevent identification of specific control gaps
Assumed control effectiveness: Risk registers that apply risk reduction credit for documented controls without evidence that those controls are consistently applied in practice overstate actual compliance risk management
Static assessments: Compliance risk assessments completed at certification and not updated when regulatory changes, organizational changes or control failures occur become progressively less accurate and less useful
Final remark: Make compliance risk reviews a governing body agenda item, covering top residual risks, control status and treatment plan progress.
ISO 37301 and its relationship with ISO 37001
ISO 37001 is the anti-bribery management system standard, covering the specific compliance obligations, controls and governance requirements for preventing, detecting and responding to bribery. ISO 37301 provides the broader CMS framework within which ISO 37001 anti-bribery controls operate as a defined compliance obligation and risk domain.
The relationship is hierarchical: ISO 37301 governs the organization's compliance management framework across all obligation categories. ISO 37001 governs the specific anti-bribery management system within that framework. Organizations certified to ISO 37001 will find that a significant portion of their CMS infrastructure, including governing body involvement, compliance function design, risk assessment methodology, due diligence controls and training programs, is already substantially implemented.
The incremental effort for ISO 37301 certification covers the expansion of the obligation identification and risk assessment process beyond anti-bribery to the full scope of the organization's compliance obligations.
Takeaway: Use existing ISO 37001 anti-bribery management system documentation as a practical foundation for designing your ISO 37301 compliance management system.
Who should implement ISO 37301?
It is particularly valuable for organizations in heavily regulated industries, those with significant international operations across multiple regulatory jurisdictions, those subject to government or institutional procurement compliance requirements and those whose governing bodies face personal liability for compliance failures.
Organizations with the most pressing business case for ISO 37301 certification include financial services firms managing regulatory capital, conduct, AML and sanctions compliance obligations simultaneously, multinational corporations with operations across jurisdictions with differing anti-corruption, data protection and employment law requirements, public sector and government-adjacent organizations where compliance accountability is a governance obligation rather than a commercial choice, professional services firms whose clients specify compliance management certification in vendor qualification criteria, and organizations in the Gulf, India and Southeast Asia where government and institutional procurement increasingly requires demonstrated compliance governance credentials.
Tip: Identify the three compliance obligations whose violation could cause the greatest penalties, license risks or reputational damage to your organization.
The certification process
Stage 2 verifies that the CMS is genuinely implemented and operational, with auditors assessing evidence of compliance obligation identification, risk assessment outputs, control operation and governing body engagement.
Stage 1 Audit
Covers the compliance obligation register, compliance risk assessment methodology and outputs, documented information framework, organizational context analysis and governing body and leadership commitment evidence. The auditor confirms that the CMS is designed to meet ISO 37301 requirements and identifies significant gaps before Stage 2.
Stage 2 Audit
Verifies operational implementation. Auditors assess the compliance obligation register for completeness and currency, review the compliance risk assessment for methodological soundness and control effectiveness evidence, interview compliance function and operational staff on obligation awareness and control application, and review governing body minutes for evidence of compliance governance involvement.
Typical Timeline
Organizations with existing compliance programs typically achieve ISO 37301 certification in 4 to 7 months from gap analysis to certificate issuance. Organizations building a CMS from a minimal baseline typically require 7 to 12 months.
Before Stage 2, confirm governing body review of compliance risks is completed and formally documented in meeting minutes.
Author's views
The convergence of anti-corruption enforcement, data protection law, financial crime regulation, ESG disclosure obligations and supply chain due diligence requirements across multiple jurisdictions simultaneously has created a compliance management challenge that informal, function-siloed compliance programs cannot govern effectively.
The standard's insistence on governing body involvement is its most important and most underappreciated requirement: compliance failures that generate the most significant organizational damage are almost always the result of governance failures at board level, not control failures at operational level. Organizations that implement ISO 37301 with genuine governing body engagement will build compliance governance that functions as a strategic risk management capability rather than a legal cost center.
How Pacific Certifications can help?
Accredited by ABIS, Pacific Certifications conducts impartial, evidence-based audits in full conformance with ISO/IEC 17021. Services include:
ISO 37301 Compliance Management System initial certification and surveillance audits
ISO 37001 Anti-Bribery Management System certification audits
Integrated management system audits covering ISO 37301, ISO 37001 and ISO 9001
Stage 1 and Stage 2 audit execution with clear, transparent audit reports
Annual surveillance and triennial recertification audits throughout the certification cycle
Contact Us
To get started with ISO 37301 Compliance Risk Assessment, contact us at support@pacificcert.com or +91-8595603096.
For training programs, contact us at trainings@pacificcert.com.
Also read: ISO 31000 and ISO 37001 for risk and anti-bribery compliance
